2

Remote Exploit Development Jobs in New York (NOW HIRING)

This is a remote position based in the United States, with occasional travel for conferences, team ... Track how threat actors exploit current events, emerging technologies, and changes in the threat ...

Remote (US or Canada) Type: US - Full-Time; Canada - Independent Contractor About Human Agency We ... AI-native product development. You'll ship product using AI as a core capability from day one - not ...

Remote Exploit Development information

What is the difference between Remote Exploit Development vs Penetration Tester?

AspectRemote Exploit DevelopmentPenetration Tester
CredentialsKnowledge of security vulnerabilities, programming, and sometimes certifications like OSCPCertifications like OSCP, CEH, and strong technical skills
Work EnvironmentTypically focused on developing exploits in controlled environments or labsConducts security assessments in client or corporate networks
Industry UsageUsed mainly in security research, offensive security, and exploit developmentUsed in cybersecurity, risk assessment, and compliance

Remote Exploit Development involves creating and testing exploits for vulnerabilities, often in a research or offensive security context. Penetration Testers simulate attacks to identify security weaknesses. While both roles require strong technical skills and security knowledge, exploit developers focus on developing exploits, whereas penetration testers perform broader security assessments.

What are the most commonly searched types of Exploit Development jobs in New York? The most popular types of Exploit Development jobs in New York are:
What job categories do people searching Remote Exploit Development jobs in New York look for? The top searched job categories for Remote Exploit Development jobs in New York are:
What cities in New York are hiring for Remote Exploit Development jobs? Cities in New York with the most Remote Exploit Development job openings:
Vulnerability Remediation Engineer

Vulnerability Remediation Engineer

Noblesoft Technologies

Raritan, NJ • Remote

Contractor

Posted 10 days ago


Job description

Job Title: Vulnerability Remediation Engineer

Location:  Raritan, NJ 08869 / REMOTE

Job Description:

  • Implement capabilities for a global Vulnerability Management program: internal/external exposure, imminent threats, prioritization, remediation facilitation.
  • Serve as technical SME for vulnerability tools and processes (Tenable, Qualys, Rapid7, or equivalent).
  • Continuously improve VM processes for coverage, efficiency, and visibility.
  • Leverage automation, analytics, and threat intelligence to improve accuracy and reduce remediation timelines.
  • Operate/optimize scanning platforms, discovery tooling, and reporting pipelines for asset visibility.
  • Partner with Infrastructure, Engineering, Application, and Cloud teams to reduce risk across environments.
  • Lead critical vulnerability identification and response exercises, including zero-day/imminent threats.
  • Develop and maintain metrics, dashboards, and executive-level reporting on posture, remediation progress, and program maturity.
  • Track and communicate remediation SLAs, risk reduction, and program improvements.

Qualifications and Skills:

  • Technical proficiency across network, system, and application layers; scanning, asset discovery, and exploit analysis
  • Hands-on experience with VM tools (e.g., Tenable.io, Qualys VMDR/WAS, Rapid7 InsightVM/AppSec) and discovery utilities (Nmap, SSLScan, Shodan, BitSight, Security Scorecard, custom scripts).
  • Knowledge in threat intel and data-driven prioritization (CVSS/CISA/EPSS).
  • Strong cloud understanding (AWS, Azure, GCP) and modern app stacks.
  • Scripting/automation (Python, PowerShell, Bash) and data analysis (SQL, Excel).
  • Scale-ready processes, metrics, dashboards, and analytics (Tableau, PowerBI).
  • Cross-functional collaboration; clear risk communication to technical and business stakeholders.
  • Knowledge of IT processes, secure baselines, and control frameworks (CIS, NIST, ISO, Microsoft, etc.).

Preferred:

  • Relevant certifications such as OSCP, GWAPT, CEH, or CSSLP.
  • Experience working in Agile and DevSecOps environments.
  • Knowledge of containerized applications and security tools (e.g., Docker, Kubernetes, etc.).
  • Understanding of regulatory compliance requirements (e.g., PCI DSS, GDPR, HIPAA).
  • Experience with penetration testing and exploit development.